act_file.php
Code: Select all
if(isset($_GET["trash"])) {
list($id, $wert) = explode("|", $_GET["trash"]);
$id = intval($id);
$wert = intval($wert);
if($wert == 1 || $wert == 0) {
$sql = "UPDATE ".DB_PREPEND."phpwcms_file SET f_pid=0, ".
"f_trash=".$wert.", f_changed=CONCAT_WS('|', f_changed, '".time()."'), ".
"f_log=CONCAT_WS('\n', f_log, 'deleted by user ".aporeplace($_SESSION["wcs_user"])."') ".
"WHERE f_id=".$id." AND f_kid=1 AND f_uid=".$_SESSION["wcs_user_id"];
$result = mysql_query($sql, $db) or die ("error while moving file to trash");
}else if($wert == 9)
{
$sql = "SELECT * FROM ".DB_PREPEND."phpwcms_file ".
"WHERE f_id=".$id;
$result = mysql_query($sql, $db) or die ("error finding file");
$myrow = mysql_fetch_array($result);
$f_uid = $myrow["f_uid"];
$f_ext = $myrow["f_ext"];
$location = getenv('DOCUMENT_ROOT').$phpwcms["root"].$phpwcms["file_path"];
$filename = $location .$f_uid ."/". $f_uid ."_". $id . ".".$f_ext ;
unlink($filename);
$sql1 = "DELETE FROM ".DB_PREPEND."phpwcms_file ".
"WHERE f_id=".$id;
$result = mysql_query($sql1, $db) or die ("error while moving file to trash");
}
}